Casino Game Penetration Test
Budget: $30 – $250 USD
I need an experienced ethical hacker to probe the security of our browser-based casino game, with the sole purpose of verifying that the underlying game logic and algorithms cannot be abused. Your task is to approach the production environment exactly as a determined attacker would, document every weakness you discover, and demonstrate practical proof-of-concept exploits where applicable.
The focus is strictly on the fairness engine—random number generation, payout calculations, client-server synchronisation, and any hidden assumptions that might let a player tilt the odds. Authentication, payments, and other surface areas are handled elsewhere, so please concentrate all effort on the game mechanics themselves.
You will receive temporary credentials to a staging copy plus source-map access to ease dynamic analysis. Feel free to employ the tools you know best: Burp Suite, Fiddler, mitmproxy, browser dev tools, custom scripts in Python or Node.js—whatever helps you uncover logical flaws and race conditions.
Deliverables:
• A concise report describing each discovered vulnerability, its impact, reproduction steps, and recommended fix
• Proof-of-concept scripts or screenshots validating the exploitability of every confirmed issue
• A short debrief call (30 min) to walk through findings and answer developer questions
All work must stay within the provided environment and follow responsible disclosure practices. If you thrive on breaking game maths and want to help us ship a rock-solid casino experience, let’s get started.
The focus is strictly on the fairness engine—random number generation, payout calculations, client-server synchronisation, and any hidden assumptions that might let a player tilt the odds. Authentication, payments, and other surface areas are handled elsewhere, so please concentrate all effort on the game mechanics themselves.
You will receive temporary credentials to a staging copy plus source-map access to ease dynamic analysis. Feel free to employ the tools you know best: Burp Suite, Fiddler, mitmproxy, browser dev tools, custom scripts in Python or Node.js—whatever helps you uncover logical flaws and race conditions.
Deliverables:
• A concise report describing each discovered vulnerability, its impact, reproduction steps, and recommended fix
• Proof-of-concept scripts or screenshots validating the exploitability of every confirmed issue
• A short debrief call (30 min) to walk through findings and answer developer questions
All work must stay within the provided environment and follow responsible disclosure practices. If you thrive on breaking game maths and want to help us ship a rock-solid casino experience, let’s get started.
Related categories:
Python
Web Security
Testing / QA
Software Testing
Test Automation
Node.js
Penetration Testing
Security Auditing